Add configurable HSTS and some other headers
This commit is contained in:
parent
df02d27674
commit
068f3c04a0
@ -58,3 +58,10 @@ secret = ""
|
||||
[auth.twitter]
|
||||
key = ""
|
||||
secret = ""
|
||||
|
||||
# Strict-Transport-Security
|
||||
[https.hsts]
|
||||
enabled = false
|
||||
max_age = 31536000
|
||||
include_subdomains = false
|
||||
preload = false
|
||||
|
@ -10,7 +10,7 @@ import (
|
||||
var (
|
||||
index_0 = []byte(`<!DOCTYPE html><html lang=en><head><meta charset=UTF-8><meta name=viewport content="width=device-width,initial-scale=1"><title>Dispatch</title><link href="https://fonts.googleapis.com/css?family=Montserrat:400,700|Roboto+Mono:400,700" rel=stylesheet><link href=/`)
|
||||
index_1 = []byte(` rel=stylesheet></head><body><div id=root></div><script>window.__ENV__=`)
|
||||
index_2 = []byte(`;</script><script src=/`)
|
||||
index_2 = []byte(`</script><script src=/`)
|
||||
index_3 = []byte(`></script></body></html>`)
|
||||
)
|
||||
|
||||
|
@ -17,7 +17,8 @@ import (
|
||||
"github.com/khlieng/dispatch/assets"
|
||||
)
|
||||
|
||||
var files = []File{
|
||||
var (
|
||||
files = []File{
|
||||
File{
|
||||
Path: "bundle.js",
|
||||
Asset: "bundle.js.gz",
|
||||
@ -52,6 +53,9 @@ var files = []File{
|
||||
},
|
||||
}
|
||||
|
||||
hstsHeader string
|
||||
)
|
||||
|
||||
type File struct {
|
||||
Path string
|
||||
Asset string
|
||||
@ -76,6 +80,17 @@ func initFileServer() {
|
||||
|
||||
hash = md5.Sum(data)
|
||||
files[1].Path = "bundle." + base64.RawURLEncoding.EncodeToString(hash[:]) + ".css"
|
||||
|
||||
if viper.GetBool("https.hsts.enabled") {
|
||||
hstsHeader = "max-age=" + viper.GetString("https.hsts.max_age")
|
||||
|
||||
if viper.GetBool("https.hsts.include_subdomains") {
|
||||
hstsHeader += "; includeSubDomains"
|
||||
}
|
||||
if viper.GetBool("https.hsts.preload") {
|
||||
hstsHeader += "; preload"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@ -112,11 +127,19 @@ func serveIndex(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
w.Header().Set("Cache-Control", "no-store")
|
||||
w.Header().Set("Content-Type", "text/html")
|
||||
w.Header().Set("Cache-Control", "no-store")
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
w.Header().Set("X-Frame-Options", "deny")
|
||||
w.Header().Set("X-XSS-Protection", "1; mode=block")
|
||||
|
||||
if hstsHeader != "" {
|
||||
w.Header().Set("Strict-Transport-Security", hstsHeader)
|
||||
}
|
||||
|
||||
if strings.Contains(r.Header.Get("Accept-Encoding"), "gzip") {
|
||||
w.Header().Set("Content-Encoding", "gzip")
|
||||
|
||||
gzw := gzip.NewWriter(w)
|
||||
renderIndex(gzw, session)
|
||||
gzw.Close()
|
||||
|
Loading…
Reference in New Issue
Block a user